Privacy Policy

Last updated: July 21, 2026

This Privacy Policy describes how VeilBrowser Inc. ("VeilBrowser", "we", "us", or "our") collects, uses, shares, and protects information that identifies or relates to you ("Personal Data") when you use our website, cloud SaaS, Local API licensing integrations, documentation, and related services (the "Service"). VeilBrowser is designed to be local-first: browser sessions run on your own machines, and we aim to hold as little operational browsing data as possible.

1. Controller and scope

For Personal Data processed in connection with the Service, the data controller is:

VeilBrowser Inc.
123 Main St, Anytown, USA
Email: privacy@veilbrowser.net

Where required, our EU representative is: VeilBrowser GmbH.

By using the Service, you acknowledge that Personal Data will be processed as described in this Policy. This Policy does not itself constitute consent where consent is a required legal basis; we will request consent separately when needed.

2. Information we collect

We collect Personal Data in these main categories:

  • Account data — name, email, authentication credentials or OAuth identifiers, organization and team membership, roles;
  • Service and profile data — cloud profile names and fingerprint/proxy configuration you choose to store with us, API keys (stored hashed), product settings;
  • Billing data — plan, invoices, payment status; card and bank details are handled by our payment processor;
  • Technical and usage data — IP address, device/OS/browser metadata, access times, referrers, API usage, launch/session events needed to operate the Service and enforce plan limits;
  • Support data — information you send us in emails, forms, or tickets.

We do not intentionally collect special categories of Personal Data (such as health, biometric, or political data), and we do not knowingly collect information about criminal convictions.

3. Purposes, legal bases, and retention

We limit collection to what is reasonably necessary for the purposes below. Where GDPR or UK GDPR applies, our legal bases include contract, legitimate interests, consent, and legal obligation as indicated.

PurposePersonal dataLegal basisRetention
Account creation and authenticationName, email address, password hashes or OAuth identifiers, organization membership and rolesPerformance of a contract (Terms of Service); legitimate interest in securing accountsFor the life of the account, then up to 90 days after deletion (or sooner on verified request where feasible)
Providing and operating the ServiceCloud profile metadata and configuration you store with us, API keys (hashed), session/usage events needed for plan limits, product settingsPerformance of a contractFor the life of the account or until you delete the data; session telemetry retained as needed for billing and abuse prevention
Billing and subscription managementBilling contact details, plan selection, invoices, payment status; payment card data is processed by our payment provider and not stored by us in fullPerformance of a contract; legal obligation (tax/accounting)For the subscription period and as required by tax and accounting laws (typically up to 7 years where applicable)
Customer supportContact details and information you provide in tickets or email, plus relevant technical/usage contextLegitimate interest in responding to requests; performance of a contractUp to 24 months after the issue is resolved, unless a longer period is needed for disputes
Security, abuse prevention, and service reliabilityIP address, device/browser type, access timestamps, referrer, error logs, rate-limit signalsLegitimate interest in securing and operating the Service; legal obligation where applicableTypically 30–180 days for logs, longer if needed for security investigations or legal claims
Product analytics and improvementAggregated or pseudonymous usage metrics (e.g. feature adoption, launch counts, API volume)Legitimate interest in improving the Service; consent where required for non-essential cookies/analyticsAggregated analytics may be retained longer in non-identifying form
Marketing communications (optional)Email address and communication preferencesConsent or soft opt-in where permitted; you may opt out at any timeUntil you unsubscribe or your account is deleted

4. Local-first execution

When you use the Local API (and optionally Cluster Manager) on your own infrastructure, browser instances and the pages you visit run on machines you control. That browsing activity — including page content, cookies in the browser profile on disk, and local session state — is not transmitted to or stored by VeilBrowser as part of normal operation.

Cloud components may receive profile configuration you sync, license/plan verification signals, and aggregate usage events (for example session start/stop or API counts) required to provide billing, limits, and product features. You decide what profile metadata to store in the cloud versus keep local.

5. How we use information

We use Personal Data to:

  • provide, secure, and maintain the Service;
  • authenticate users and manage organizations and API keys;
  • process payments and enforce plan limits;
  • communicate about your account, security, and product updates;
  • provide customer support;
  • detect abuse, fraud, and security incidents;
  • improve the Service through aggregated analytics where permitted;
  • comply with law and enforce our Terms of Service.

We do not sell your Personal Data.

6. Sharing with processors and others

We share Personal Data only when needed to operate the Service or as required by law, including with:

  • Payment processors (e.g. Stripe) to process subscriptions and invoices;
  • Infrastructure and hosting providers that store or process account and service data under contract;
  • Email and communications providers to deliver transactional and (if opted in) marketing messages;
  • Analytics providers where enabled, to understand product usage;
  • Identity providers if you sign in with OAuth;
  • professional advisors, or authorities when required by law, legal process, or to protect rights, safety, and security;
  • a successor entity in connection with a merger, acquisition, or asset sale, subject to appropriate safeguards.

Processors are engaged under contractual terms requiring appropriate protection of Personal Data. We do not allow them to use your data for their own unrelated marketing.

7. International transfers

We may process Personal Data in countries other than where you live. Where we transfer Personal Data from the EEA/UK/Switzerland to countries without an adequacy decision, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms, and supplementary measures where needed.

8. Security

We implement technical and organizational measures appropriate to the risk, including encryption in transit (TLS), access controls, hashed API keys and passwords, least-privilege access for staff, and monitoring for abuse. No method of transmission or storage is completely secure; you are responsible for safeguarding credentials and securing self-hosted deployments.

Payment card data is handled by our payment provider; we do not store full card numbers on our systems.

9. Your rights (EEA, UK, and similar)

Depending on your location, you may have rights to:

  • access a copy of your Personal Data;
  • rectify inaccurate or incomplete data;
  • erase data where no longer needed or where consent is withdrawn;
  • restrict or object to certain processing;
  • data portability for data you provided under contract or consent;
  • withdraw consent at any time (without affecting prior processing);
  • lodge a complaint with your local supervisory authority.

To exercise these rights, email privacy@veilbrowser.net. We will respond within one month where GDPR applies (extendable by up to two months for complex requests). We may need to verify your identity before acting on a request.

10. California and similar US state rights

If you are a California resident (or resident of another US state with similar laws), you may have rights to know, access, correct, delete, and obtain a portable copy of Personal Data, and to opt out of "sale" or "sharing" of Personal Data for cross-context behavioral advertising. We do not sell Personal Data for money. We will not discriminate against you for exercising privacy rights.

Submit requests to privacy@veilbrowser.net. We aim to respond to verifiable requests within 45 days (or as otherwise required by applicable law).

11. Cookies and similar technologies

We use cookies and similar technologies that are necessary for authentication, security, and basic site functionality. We may also use analytics or preference cookies where permitted. You can control cookies through your browser settings; disabling certain cookies may affect login or dashboard features.

12. Children

The Service is not directed to children. We do not knowingly collect Personal Data from children under 13 (or under 16 in the EEA/UK where applicable). If you believe a child has provided us Personal Data, contact privacy@veilbrowser.net and we will take steps to delete it.

13. Automated decision-making

We do not use automated decision-making or profiling that produces legal or similarly significant effects solely by automated means without human involvement.

14. Third-party links

The Service may link to third-party sites or services. Their privacy practices are their own. Review their policies before providing Personal Data to them.

15. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the revised Policy on this page and update the "Last updated" date. Material changes may also be communicated by email or in-product notice. Continued use of the Service after the effective date means the updated Policy applies. Where a change requires fresh consent, we will request it.

16. Contact

For privacy questions, complaints, or rights requests, contact:

VeilBrowser Inc.
123 Main St, Anytown, USA
Privacy: privacy@veilbrowser.net
Legal: legal@veilbrowser.net

This document is a template. Replace company placeholders in apps/web/src/lib/constants/site.ts before relying on it in production. It is not legal advice.